Vulnerabilities

Major Security Flaws in Zyxel Firewalls, Access Points, NAS Devices

Major Security Flaws in Zyxel Firewalls, Access Points, NAS Devices 30/11/2023 at 20:18 By Ryan Naraine Zyxel patches at least 15 security flaws that expose users to authentication bypass, command injection and denial-of-service attacks. The post Major Security Flaws in Zyxel Firewalls, Access Points, NAS Devices appeared first on SecurityWeek. This article is an excerpt […]

Major Security Flaws in Zyxel Firewalls, Access Points, NAS Devices Read More »

Google Patches Seventh Chrome Zero-Day of 2023

Google Patches Seventh Chrome Zero-Day of 2023 29/11/2023 at 16:46 By Ionut Arghire The latest Chrome security update addresses the seventh exploited zero-day vulnerability documented in the browser in 2023. The post Google Patches Seventh Chrome Zero-Day of 2023 appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Google Patches Seventh Chrome Zero-Day of 2023 Read More »

Exploitation of Critical ownCloud Vulnerability Begins

Exploitation of Critical ownCloud Vulnerability Begins 28/11/2023 at 18:01 By Ionut Arghire Threat actors have started exploiting a critical ownCloud vulnerability leading to sensitive information disclosure. The post Exploitation of Critical ownCloud Vulnerability Begins appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Exploitation of Critical ownCloud Vulnerability Begins Read More »

Critical ownCloud Flaws Lead to Sensitive Information Disclosure, Authentication Bypass

Critical ownCloud Flaws Lead to Sensitive Information Disclosure, Authentication Bypass 27/11/2023 at 19:46 By Ionut Arghire Three critical vulnerabilities in ownCloud could lead to sensitive information disclosure and authentication and validation bypass. The post Critical ownCloud Flaws Lead to Sensitive Information Disclosure, Authentication Bypass appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Critical ownCloud Flaws Lead to Sensitive Information Disclosure, Authentication Bypass Read More »

Microsoft Offers Up to $20,000 for Vulnerabilities in Defender Products

Microsoft Offers Up to $20,000 for Vulnerabilities in Defender Products 22/11/2023 at 17:17 By Ionut Arghire Microsoft invites researchers to new bug bounty program focused on vulnerabilities in its Defender products. The post Microsoft Offers Up to $20,000 for Vulnerabilities in Defender Products appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS

Microsoft Offers Up to $20,000 for Vulnerabilities in Defender Products Read More »

Citrix, Gov Agencies Issue Fresh Warnings on CitrixBleed Vulnerability

Citrix, Gov Agencies Issue Fresh Warnings on CitrixBleed Vulnerability 22/11/2023 at 15:17 By Ionut Arghire Administrators are urged to patch the recent CitrixBleed NetScaler vulnerability as LockBit starts exploiting it. The post Citrix, Gov Agencies Issue Fresh Warnings on CitrixBleed Vulnerability appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View

Citrix, Gov Agencies Issue Fresh Warnings on CitrixBleed Vulnerability Read More »

Microsoft announces Defender bug bounty program

Microsoft announces Defender bug bounty program 22/11/2023 at 14:47 By Helga Labus Microsoft has announced a new bug bounty program aimed at unearthing vulnerabilities in Defender-related products and services, and is offering participants the possibility to earn up to $20,000 for the most critical bugs. The Microsoft Defender bug bounty program Microsoft Defender includes various

Microsoft announces Defender bug bounty program Read More »

Microsoft Paid Out $63 Million Since Launch of First Bug Bounty Program 10 Years Ago

Microsoft Paid Out $63 Million Since Launch of First Bug Bounty Program 10 Years Ago 21/11/2023 at 15:16 By Ionut Arghire Over the past ten years, Microsoft has handed out $63 million in rewards as part of its bug bounty programs. The post Microsoft Paid Out $63 Million Since Launch of First Bug Bounty Program

Microsoft Paid Out $63 Million Since Launch of First Bug Bounty Program 10 Years Ago Read More »

Organizations’ serious commitment to software risk management pays off

Organizations’ serious commitment to software risk management pays off 21/11/2023 at 07:32 By Industry News There has been a significant decrease in vulnerabilities found in target applications – from 97% in 2020 to 83% in 2022 – an encouraging sign that code reviews, automated testing and continuous integration are helping to reduce common programming errors,

Organizations’ serious commitment to software risk management pays off Read More »

Over a Dozen Exploitable Vulnerabilities Found in AI/ML Tools

Over a Dozen Exploitable Vulnerabilities Found in AI/ML Tools 17/11/2023 at 17:45 By Ionut Arghire Bug hunters uncover over a dozen exploitable vulnerabilities in tools used to build chatbots and other types of AI/ML models. The post Over a Dozen Exploitable Vulnerabilities Found in AI/ML Tools appeared first on SecurityWeek. This article is an excerpt

Over a Dozen Exploitable Vulnerabilities Found in AI/ML Tools Read More »

Microsoft Patches Sensitive Information Disclosure Vulnerability in Azure CLI

Microsoft Patches Sensitive Information Disclosure Vulnerability in Azure CLI 15/11/2023 at 18:02 By Ionut Arghire Microsoft provided guidance on an Azure CLI bug leading to the exposure of sensitive information through GitHub Actions logs. The post Microsoft Patches Sensitive Information Disclosure Vulnerability in Azure CLI appeared first on SecurityWeek. This article is an excerpt from

Microsoft Patches Sensitive Information Disclosure Vulnerability in Azure CLI Read More »

SAP Patches Critical Vulnerability in Business One Product

SAP Patches Critical Vulnerability in Business One Product 15/11/2023 at 17:01 By Ionut Arghire SAP released a hotfix for a critical-severity improper access control vulnerability in Business One product installation. The post SAP Patches Critical Vulnerability in Business One Product appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original

SAP Patches Critical Vulnerability in Business One Product Read More »

Chipmaker Patch Tuesday: Intel, AMD Address Over 130 Vulnerabilities

Chipmaker Patch Tuesday: Intel, AMD Address Over 130 Vulnerabilities 15/11/2023 at 13:17 By Eduard Kovacs Intel and AMD have informed their customers about a total of more than 130 vulnerabilities found in their products. The post Chipmaker Patch Tuesday: Intel, AMD Address Over 130 Vulnerabilities appeared first on SecurityWeek. This article is an excerpt from

Chipmaker Patch Tuesday: Intel, AMD Address Over 130 Vulnerabilities Read More »

Critical Authentication Bypass Flaw in VMware Cloud Director Appliance

Critical Authentication Bypass Flaw in VMware Cloud Director Appliance 15/11/2023 at 00:32 By Ryan Naraine VMware flaw carries a CVSS severity-score of 9.8/10 and can be exploited to bypass login restrictions when authenticating on certain ports. The post Critical Authentication Bypass Flaw in VMware Cloud Director Appliance appeared first on SecurityWeek. This article is an

Critical Authentication Bypass Flaw in VMware Cloud Director Appliance Read More »

Microsoft Warns of Critical Bugs Being Exploited in the Wild

Microsoft Warns of Critical Bugs Being Exploited in the Wild 14/11/2023 at 23:47 By Ryan Naraine Patch Tuesday: Redmond’s security response team flags two vulnerabilities — CVE-2023-36033 and CVE-2023-36036 — already being exploited in the wild. The post Microsoft Warns of Critical Bugs Being Exploited in the Wild appeared first on SecurityWeek. This article is

Microsoft Warns of Critical Bugs Being Exploited in the Wild Read More »

Protected Virtual Machines Exposed to New ‘CacheWarp’ AMD CPU Attack

Protected Virtual Machines Exposed to New ‘CacheWarp’ AMD CPU Attack 14/11/2023 at 21:46 By Eduard Kovacs CacheWarp is a new attack method affecting a security feature present in AMD processors that can pose a risk to virtual machines. The post Protected Virtual Machines Exposed to New ‘CacheWarp’ AMD CPU Attack appeared first on SecurityWeek. This

Protected Virtual Machines Exposed to New ‘CacheWarp’ AMD CPU Attack Read More »

Adobe Patch Tuesday: Critical Bugs in Acrobat, Reader, ColdFusion

Adobe Patch Tuesday: Critical Bugs in Acrobat, Reader, ColdFusion 14/11/2023 at 21:46 By Ryan Naraine Adobe patches 72 security bugs and calls special attention to code-execution defects in the widely deployed Acrobat and Reader software. The post Adobe Patch Tuesday: Critical Bugs in Acrobat, Reader, ColdFusion appeared first on SecurityWeek. This article is an excerpt

Adobe Patch Tuesday: Critical Bugs in Acrobat, Reader, ColdFusion Read More »

SysAid Zero-Day Vulnerability Exploited by Ransomware Group

SysAid Zero-Day Vulnerability Exploited by Ransomware Group 09/11/2023 at 13:32 By Eduard Kovacs CVE-2023-47246 zero-day vulnerability in SysAid IT service management software has been exploited by Cl0p ransomware affiliates. The post SysAid Zero-Day Vulnerability Exploited by Ransomware Group appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

SysAid Zero-Day Vulnerability Exploited by Ransomware Group Read More »

Critical Vulnerabilities Expose Veeam ONE Software to Code Execution

Critical Vulnerabilities Expose Veeam ONE Software to Code Execution 07/11/2023 at 19:46 By Ionut Arghire Veeam Software has rolled out patches to cover code execution vulnerabilities in its Veeam ONE IT monitoring product. The post Critical Vulnerabilities Expose Veeam ONE Software to Code Execution appeared first on SecurityWeek. This article is an excerpt from SecurityWeek

Critical Vulnerabilities Expose Veeam ONE Software to Code Execution Read More »

Exploitation of Critical Confluence Vulnerability Begins

Exploitation of Critical Confluence Vulnerability Begins 06/11/2023 at 15:47 By Ionut Arghire Threat actors have started exploiting a recent critical vulnerability in Confluence Data Center and Confluence Server. The post Exploitation of Critical Confluence Vulnerability Begins appeared first on SecurityWeek. This article is an excerpt from SecurityWeek RSS Feed View Original Source

Exploitation of Critical Confluence Vulnerability Begins Read More »

Scroll to Top